Trust & Verification
No DPRK Allowed -
How We Vet Our Auditors
Identity-verified, sanctions-screened and contractually bound.
Web3 runs on pseudonyms, which works fine for a Discord handle and a lot less well for the person reading your unreleased contracts weeks before anyone else sees them. When you hire an audit firm you hand a small group of people deep access to the most sensitive code you own, and you should know exactly who they are. We do. Nobody joins us without clearing the same set of checks first.
Researcher invited
candidate intake
Identity verification
Gov ID + liveness
Sanctions & watchlist check
OFAC / EU / UN
Payout wallet screening
illicit-activity DBs
Signed agreement + data consent
before day one
All checks pass?
Approved & onboarded
cleared to start
Continuous re-screening
loops back into screening, ongoing
If any check fails
Rejected / manual review
1. Identity verification
Every researcher verifies a government-issued ID and passes a liveness and biometric check, so we know the document belongs to the person holding it.
2. Sanctions and watchlist screening
Every verified identity is screened against global sanctions and watchlists (OFAC, EU, UN and their equivalents) and against high-risk and embargoed jurisdictions. If someone is sanctioned, or working out of a region we are barred from dealing with, that is where it ends for them.
DPRK-linked operators have spent years getting hired into crypto teams as developers and freelancers. The only place to catch that is at hiring, so that is where we do it.
3. Payout screening
Payout addresses are screened against illicit-activity databases before any funds move. Knowing who someone is says nothing about where their payout address has been, so that gets its own check.
4. Signed and consented
Every researcher signs a contractor agreement and a data-protection consent before starting. Confidentiality and the limits on what they can access are written into it, with their signature underneath.
5. Ongoing, not a signup checkbox
A clean check last year tells you nothing about today. Screening runs again automatically, for as long as someone works with us.
Accountability
Every identity is verified and kept on file, so any piece of work ties back to a specific person who signed for it. If something ever went wrong we would know exactly who to go to, and they know that going in.
Anyone who reads your code has a name on file and a signature behind them. Worth asking whoever else you let near your protocol whether they can say the same.
Questions about how we vet the team on your engagement? Start at pashov.com/request-audit, or reach out directly via Telegram.